ISAE 3000: the standard for assurance on everything except the financial statements

IT-audit8 min read·
K

Kees van der Vlies

Partner | IT Auditor

Also available in:Nederlands

ISAE 3000 is the overarching international standard for assurance engagements on non-financial information. The full name is ISAE 3000 (Revised), Assurance Engagements Other than Audits or Reviews of Historical Financial Information, issued by the IAASB. Everything an auditor provides in assurance outside the classic financial statement audit essentially runs through this standard.

That makes ISAE 3000 the foundation under a whole family of reports. ISAE 3402, for outsourced processes affecting clients' financial statements, is a specific elaboration of it. The same goes for ISAE 3410 (greenhouse gas statements) and for most European SOC 2 reports, which are formally issued under ISAE 3000. Understand how ISAE 3000 works and you understand the whole stack.

What is ISAE 3000 used for?

In our practice, ISAE 3000 engagements come in a few recurring forms.

Assurance on information security and IT management. A client or regulator wants independent assurance that security measures or management processes operate, but the scope does not fit a certification or an ISAE 3402. Think of a report on the controls around a specific platform or service.

Privacy assurance. A processor that wants to demonstrate to its clients that the agreements in the data processing agreement and the relevant GDPR obligations are met has an ISAE 3000 report issued on exactly that.

Algorithm and AI assurance. A growing category: independent assurance on the controls around algorithms and AI systems, for example for public-sector organizations that are accountable for them. We covered this in a separate article on algorithm assurance under ISAE 3000.

Sector-specific frameworks. Several Dutch assessment regimes are built on ISAE 3000, including the DigiD assessments we perform as auditors.

And SOC 2: outside the US, ISAE 3000 is the formal basis under which auditors issue a SOC 2 report. The report tests against the Trust Services Criteria in substance; the opinion on top is an ISAE 3000 opinion.

How is an ISAE 3000 engagement structured?

Every ISAE 3000 engagement has the same building blocks. There is a subject matter (the processes, systems or information assurance is given about), there are criteria (the framework tested against, for example a standard, contractual agreements or the organization's own control objectives), there is a responsible party making an assertion, and there is an auditor who examines it independently and issues an opinion.

That freedom in choosing criteria is the strength and at the same time the caveat of the standard. Criteria have to be relevant, complete, reliable, neutral and understandable. A report against vague or conveniently light criteria may formally qualify, but it will not convince the reader. The value of an ISAE 3000 report stands or falls with the question: what exactly was tested against?

Reasonable or limited assurance

ISAE 3000 has two levels of assurance, and the difference matters to the reader of the report.

With reasonable assurance the auditor performs extensive testing and words the opinion positively: the controls are effective, or the information is correct in all material respects. This level is comparable to a financial statement audit and is what users of assurance reports generally expect.

With limited assurance the procedures are lighter, mostly inquiries and analytical reviews, and the conclusion is worded negatively: nothing came to our attention causing us to believe the information is misstated. That reads like a subtle difference, but the level of assurance is genuinely lower, and so is the price.

Which level fits depends on what the user of the report needs it for. An accountant who wants to rely on it, or a regulator basing a decision on it, is usually not served by limited assurance. For a first year or an internal improvement programme it can be a deliberate interim step.

Type I and Type II

As with ISAE 3402, an ISAE 3000 report on controls can be a point-in-time assessment (design and implementation at a reference date) or cover operating effectiveness over a period. For reports that third parties rely on, the period-based report is the norm. What that means for the observation period and the evidence burden is covered in our article on the ISAE 3402 Type II observation period; the mechanics are the same under ISAE 3000.

When do you choose ISAE 3000?

The choice comes down to one question: what does your client want assurance about? If your service affects clients' financial statements, ISAE 3402 is the specific and recognizable route. If it concerns the security, availability and privacy of a SaaS service and the market asks for a recognizable framework, SOC 2 (under ISAE 3000) is the logical form. If it concerns something else, from privacy compliance to algorithm governance to a sector-specific framework, a tailored ISAE 3000 report is the way to go.

Secure Audit performs ISAE 3000 engagements in information security, IT management, privacy and algorithms, alongside our ISAE 3402 and SOC 2 work. Our approach, cost factors and frequently asked questions are on the ISAE 3000 audit page. If you are unsure which report your clients actually need, we help you find the question behind the question.

Frequently asked questions

What is the difference between ISAE 3000 and ISAE 3402?+

ISAE 3000 is the broad international standard for assurance on non-financial information, applicable to almost any subject matter. ISAE 3402 is a specific elaboration of it for service organizations whose processes affect their clients' financial reporting. Every ISAE 3402 engagement belongs to the family, but an ISAE 3000 report can cover far more topics.

What is the difference between reasonable and limited assurance?+

With reasonable assurance the auditor issues a positively worded opinion after extensive testing: the controls operate effectively. With limited assurance the conclusion is worded negatively: nothing came to the auditor's attention indicating otherwise. Limited assurance takes less work and gives less certainty; report users usually ask for reasonable assurance.

What is ISAE 3000 used for in practice?+

Assurance on information security, privacy and GDPR compliance, IT management processes, algorithms and AI systems, sustainability information, and sector-specific frameworks such as the Dutch DigiD assessments. Anywhere a client or regulator wants independent assurance about something other than the financial statements.

Is a SOC 2 report the same as an ISAE 3000 report?+

In Europe, often yes in practice: auditors outside the US generally issue SOC 2 reports under ISAE 3000. The report then tests against the AICPA Trust Services Criteria, with an ISAE 3000 opinion on top. The substance is SOC 2, the formal basis is ISAE 3000.

Need help with it-audit?

Independent assurance reports for service organizations. We work with you to determine which type of report fits your situation and what your clients or regulators expect.

Explore IT-Audit Services

About the author

K
Kees van der Vlies

Partner | IT Auditor

Back to knowledge base

Have a question?

Get in touch for advice on IT audit, compliance and information security.

Contact us